Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-2719-1 Moderate: Poppler Arbitrary Code Execution

debian
Calendar Grey July 11, 2013
Debian Logo
Serious flaws found in poppler; users urged to upgrade to enhance protection from possible threats.
Multiple vulnerabilities were discovered in the poppler PDF rendering library

Summary

Multiple vulnerabilities were discovered in the poppler PDF rendering
library.

CVE-2013-1788

Multiple invalid memory access issues, which could potentially lead
to arbitrary code execution if the user were tricked into opening a
malformed PDF document.

CVE-2013-1790

An uninitialized memory issue, which could potentially lead to
arbitrary code execution if the user were tricked into opening a
malformed PDF document.

For the oldstable distribution (squeeze), these problems have been fixed in
version 0.12.4-1.2+squeeze3.

For the stable (wheezy), testing (jessie), and unstable (sid)
distributions, these problems have been fixed in version 0.18.4-6.

We recommend that you upgrade your poppler packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: poppler
CVE ID: CVE-2013-1788 CVE-2013-1790

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here